Project

General

Profile

Actions

Support #2956

closed

Beginner Guide Please about Windows 64-bit installer: Suricata-4.1.3-1-64bit.msi

Added by Hanif Prasetiyo almost 5 years ago. Updated about 4 years ago.

Status:
Closed
Priority:
Low
Assignee:
-
Affected Versions:
Label:
Beginner

Description

hello guys, noob question here. I try to install Windows 64-bit installer: Suricata-4.1.3-1-64bit.msi under Windows 7. Is there any guide I can follow? coz I'm kinda confused with the guide in https://redmine.openinfosecfoundation.org/projects/suricata/wiki/Windows and https://redmine.openinfosecfoundation.org/attachments/download/1175/SuricataWinInstallationGuide_v1.4.3.pdf. Those 2 guide doesn't tell me about installing npcap (https://nmap.org/npcap/) but the tools itself try to tell me to install npcap. After i try to install npcap and try to run suricata i've got this error:

C:\Program Files\Suricata>suricata.exe -c suricata.yaml -i 192.168.10.6
3/5/2019 -- 09:31:54 - <Info> - Running as service: no
3/5/2019 -- 09:31:56 - <Info> - translated 192.168.10.6 to pcap device \Device\NPF_{3221065E-8591-4573-8FC6-E2416A318579}
Error opening file C:\Program Files\Suricata\log\suricata.log
3/5/2019 -- 09:31:56 - <Notice> - This is Suricata version 4.1.3 RELEASE
3/5/2019 -- 09:31:56 - <Warning> - [ERRCODE: SC_WARN_DEFAULT_WILL_CHANGE(317)] - in 5.0 the default for decoder event stats will go from 'decoder.<proto>.<event>' to 'decoder.event.<proto>.<event>'. S
ee ticket #2225. To suppress this message, set stats.decoder-events-prefix in the yaml.
3/5/2019 -- 09:31:56 - <Error> - [ERRCODE: SC_ERR_FOPEN(44)] - Error opening file: "C:\Program Files\Suricata\log/fast.log": Permission denied
3/5/2019 -- 09:31:56 - <Warning> - [ERRCODE: SC_ERR_INVALID_ARGUMENT(13)] - output module setup failed
3/5/2019 -- 09:31:56 - <Error> - [ERRCODE: SC_ERR_FOPEN(44)] - Error opening file: "C:\Program Files\Suricata\log/eve.json": Permission denied
3/5/2019 -- 09:31:56 - <Warning> - [ERRCODE: SC_ERR_INVALID_ARGUMENT(13)] - output module setup failed
3/5/2019 -- 09:31:56 - <Error> - [ERRCODE: SC_ERR_FOPEN(44)] - Error opening file: "C:\Program Files\Suricata\log/stats.log": Permission denied
3/5/2019 -- 09:31:56 - <Warning> - [ERRCODE: SC_ERR_INVALID_ARGUMENT(13)] - output module setup failed
3/5/2019 -- 09:31:56 - <Warning> - [ERRCODE: SC_WARN_NO_STATS_LOGGERS(261)] - stats are enabled but no loggers are active
3/5/2019 -- 09:31:57 - <Warning> - [ERRCODE: SC_ERR_FOPEN(44)] - Error opening file: "C:\Program Files\Suricata\\\threshold.config": No such file or directory
3/5/2019 -- 09:32:01 - <Warning> - [ERRCODE: SC_ERR_NIC_OFFLOADING(284)] - NIC offloading on \Device\NPF_{3221065E-8591-4573-8FC6-E2416A318579}: Checksum IPv4 Rx: 1 Tx: 1 IPv6 Rx: 0 Tx: 0 LSOv1 IPv4:
1 LSOv2 IPv4: 0 IPv6: 0
3/5/2019 -- 09:32:01 - <Notice> - all 2 packet processing threads, 2 management threads initialized, engine started.

Hope somebody can help me and guide me the proper way to use suricata. Thank you...


Files

Screenshot_2.png (24.4 KB) Screenshot_2.png When i try to set suricata.exe with privileges Hanif Prasetiyo, 05/03/2019 08:14 PM
Screenshot_3.png (26.1 KB) Screenshot_3.png Hanif Prasetiyo, 05/24/2019 10:06 PM
Screenshot_4.png (24.2 KB) Screenshot_4.png Hanif Prasetiyo, 06/08/2019 06:13 AM
Screenshot_4.png (24.2 KB) Screenshot_4.png Hanif Prasetiyo, 06/08/2019 11:41 AM
Screenshot_5.png (108 KB) Screenshot_5.png Hanif Prasetiyo, 06/09/2019 08:24 AM
Screenshot_6.png (371 KB) Screenshot_6.png Hanif Prasetiyo, 06/11/2019 02:33 PM
stats.log (200 KB) stats.log Hanif Prasetiyo, 06/11/2019 08:50 PM
eve.json (351 KB) eve.json Hanif Prasetiyo, 06/11/2019 08:50 PM
Actions

Also available in: Atom PDF